Klogserver is a logging server product with a vulnerability profile centered on OS command injection, reflecting risks inherent to systems that parse and execute log-related operations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Klogserver over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35729CRITICAL KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter. | Dec 27, 2020 | 9.8 | 91 | NO | YES |
CVE-2021-3317HIGH KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter. | Jan 26, 2021 | 8.8 | 59 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Klogserver.
Media articles that mention a CVE ID that affects a product developed by Klogserver — matched by CVE ID, not by vendor name.